VDB
CVE-2011-1088
CVE-2011-1088
PUBLISHED
CVSS 5.800000190734863 MEDIUM
Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.
EPSS 16.36% · 95.0th percentile
Risk Scores
CVSS 2.0
5.800000190734863
EPSS Score
16.36%
95.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Maven | org.apache.tomcat:tomcat | 7.0.0 |
| n/a | n/a | n/a |
| apache | tomcat | 7.0.0, 7.0.1, 7.0.2 |
Timeline
- Mar 14, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
References
- tomcat-servletsecurity-sec-bypass(65971) vdb
- 20110315 [SECURITY] CVE-2011-1088 Apache Tomcat security constraint bypass mailing-list
- 43684 third-party-advisory
- 46685 vdb
- ADV-2011-0563 vdb
- http://tomcat.apache.org/security-7.html url
- http://svn.apache.org/viewvc?view=revision&revision=1076587 url
- 71027 vdb
- 1025215 vdb
- [announce] 20110302 [SECURITY] Tomcat 7 ignores @ServletSecurity annotations mailing-list
- http://svn.apache.org/viewvc?view=revision&revision=1076586 url
- [users] 20110302 Re: @DenyAll does nothing mailing-list
- http://svn.apache.org/viewvc?view=revision&revision=1077995 url
- [users] 20110302 Re: @DenyAll does nothing mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2011-1088 advisory
- https://github.com/apache/tomcat/commit/f528992ec6cd7b62c9ced5b3a7dc4cda6bfd1a5e url
- https://github.com/apache/tomcat/commit/ee627412570268df47a075f5d4dc5f7debf39fad url
- https://github.com/apache/tomcat/commit/ece65c1a428094b1c6c17de3d7593f64e1bb1286 url
- https://github.com/apache/tomcat/commit/dd10265436ea8b2fe35f1a8b09bc7390acbea269 url
- https://github.com/apache/tomcat/commit/dbac5e24759954daed3c584abb5d466fcf42dd4b url
…and 17 more